[UPDATED] Security Advisory: Node.JS Vulnerability CVE-2015-8027 and CVE-2015-6764

Elizabeth -

**NEW UPDATE (as of 16:45 UTC 8-Dec-2015)**

SmartOS Users

New releases of the node.js packages have been added to the 2014Q4 pkgsrc repository. The following latest package releases address the vulnerabilities outlined in this notice:

  • nodejs-0.12.9.tgz
  • nodejs-4.2.3.tgz

If you are running on a SmartOS image that is using a different pkgsrc repository, you can still install the above by using the following command:

$ pkg_add http://pkgsrc.joyent.com/packages/SmartOS/2014Q4/x86_64/All/nodejs-0.12.9.tgz


$ pkg_add http://pkgsrc.joyent.com/packages/SmartOS/2014Q4/x86_64/All/nodejs-4.2.3.tgz


You can visit the Node.js website for more information about these vulnerabilities, and the specific releases that have been identified as vulnerable.

Please also refer to our most recent OpenSSL Security Advisory for details on the Node.js versions affected by the most recent OpenSSL CVE's.


Linux Users

Please check the notices applicable to the Linux Distro you are using for the necessary remedial actions:

Debian: CVE-2015-8027 and CVE-2015-6764

Centos/Red Hat/Fedora: CVE-2015-8027 and CVE-2015-6764

Ubuntu: CVE-2015-8027 and CVE-2015-6764


This notice is to advise all Joyent Public Cloud (JPC) and SmartDataCenter (SDC) customers of the recently-identified Node.js security vulnerabilities CVE-2015-8027 and CVE-2015-6764. In the next coming days, Joyent will pro-actively update this notice confirming actions taken by Joyent, as well as provide specific details on any required actions that will need to be taken by both JPC and SDC customers. 

For now, you can visit this Node.js website to obtain additional details. Again, we will update this notice with more information within the next several days, specific to actions that may be required by all JPC and SDC customers. Your attention to this matter is appreciated.

At any time, please do not hesitate to contact our Support team by raising a ticket at https://help.joyent.com or by email to support@joyent.com if you have any questions or concerns.

Have more questions? Submit a request


Article is closed for comments.